Thursday, October 1, 2026

EncryptHub Turns Brave Support Into a Dropper; MMC Flaw Completes the Run

Trustwave SpiderLabs researchers have uncovered a sophisticated EncryptHub campaign that ingeniously abuses the Brave Support platform to deliver malicious payloads, leveraging the recently disclosed CVE-2025-26633 vulnerability in Microsoft Management Console (MMC).

Dubbed MSC EvilTwin, this flaw enables attackers to execute arbitrary code via manipulated .msc files, allowing EncryptHub also known as LARVA-208 or Water Gamayun to infiltrate systems through a blend of social engineering and technical exploitation.

The group, which has compromised over 618 organizations worldwide since February 2025, targets sectors including Web3 developers and gaming platforms like Steam, deploying infostealers and ransomware.

Threat Group Exploits Social Engineering

In this latest operation, attackers impersonate IT support via Microsoft Teams requests, establishing remote sessions to execute PowerShell commands that fetch and run scripts from domains like cjhsbam[.]com.

These scripts drop benign and malicious .msc files, exploiting MMC’s path resolution to load payloads from deceptive directories such as en-US folders, ultimately retrieving encrypted commands from C2 servers for persistence and data exfiltration.

Brave Support
Malicious payloads are deployed to a compromised system.

The attack chain begins with a PowerShell invocation bypassing execution policies to download runner.ps1, which plants dual .msc files one legitimate and one altered to replace placeholders like “htmlLoaderUrl” with C2 URLs pointing to build.ps1.

This secondary script harvests system details, decrypts AES-encrypted instructions, and deploys tools like Fickle Stealer, a PowerShell-based infostealer targeting sensitive files, cryptocurrency wallets, and browser data.

SpiderLabs’ analysis reveals EncryptHub’s evolution from script-based loaders to Golang-compiled binaries, including SilentCrystal, which creates mock directories mimicking “C:\Windows \System32” (note the trailing space) to evade detection.

Brave Support
SilentCrystal attack chain.

SilentCrystal abuses Brave Support by uploading ZIP archives containing payloads, using hardcoded API keys to fetch download links and execute them via the MMC vulnerability.

This tactic circumvents restrictions on new user uploads, indicating the actors maintain privileged accounts on the platform for stealthy distribution.

Backdoors Enhance Persistence

Further pivoting from C2 infrastructure uncovered additional Golang tools, such as a SOCKS5 proxy backdoor operating in client or server modes.

In client mode, it connects to hardcoded C2 endpoints, relaying machine info including username, domain, admin rights, public IP, geolocation, and ISP via Telegram notifications formatted for rapid attacker assessment.

Server mode establishes a SOCKS5 tunneling setup with self-signed TLS certificates using “Reverse Socks” as the common name, facilitating concurrent connections through goroutines for scalable command-and-control.

Associated domains like safesurf.fastdomain-uoemathhvq.workers.dev host payloads such as pay.ps1, which generate fake browser traffic to mask C2 activity while displaying decoy pop-ups like “System Configuration” installations.

SpiderLabs also identified rivatalk.net, a fake video conferencing site registered in July 2025, impersonating legitimate platforms to deliver MSI installers requiring access codes.

These installers sideload malicious DLLs via Symantec’s ELAM binary, spawning PowerShell to fetch and execute encrypted payloads that maintain persistent C2 connections.

This multi-layered approach underscores EncryptHub’s adaptability, combining social lures with zero-day exploits to bypass defenses.

As campaigns intensify, organizations must prioritize patching CVE-2025-26633, enhancing user training against impersonation, and deploying behavioral analytics to detect anomalous PowerShell and MMC executions.

Trustwave emphasizes proactive threat hunting aligned with MITRE frameworks to counter such evolving adversaries.

Indicators of Compromise (IOCs)

TypeIndicator
Domainrivatalk.net
Domain0daydreams.net
Domaincjhsbam.com
Domainsafesurf.fastdomain-uoemathhvq.workers.dev
IP185.33.86.220

AWS Security Services: 10-Point Executive Checklist - Download for Free

Aman Mishra
Aman Mishra
Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Axios Flaws Let Attackers Bypass Proxy Controls and Trigger SSRF Attacks

Axios maintainers have disclosed several high-severity security vulnerabilities that...

China-Nexus Hackers Compromise 350 Systems Across Asia With New Antino Backdoor

A China-nexus cyber-espionage campaign that compromised approximately 350 endpoints...

Multiple TeamViewer Vulnerabilities Enable RCE, Access Control Bypass and Privilege Escalation

TeamViewer has issued security bulletin TV-2026-1010 to address five...

CloudSyncD Uses Invisible Unicode to Hide Phished Mac Passwords in Plain Sight

A new macOS backdoor, tracked as CloudSyncD, that masquerades...

Researchers Find 543,699 Active Credentials Leaked in Public GitHub Repos

Security researchers have identified 543,699 unique credentials that remain...

HPE Instant On AP Flaws Let Unauthenticated Attackers Execute Arbitrary Commands

HPE has released security updates for its Networking Instant...

Multiple ModSecurity Vulnerabilities Let Attackers Bypass WAF Rules and Execute Malicious Requests

OWASP ModSecurity has disclosed multiple vulnerabilities that could let...

Related Articles

Recent News